Veeam Backup & Replication

Our sources currently list 42 known vulnerabilities affecting Veeam Backup & Replication. 13 are rated critical severity. 4 of 42 are actively exploited according to CISA, the most recent added 17 October 2024.

Last updated: 22 July 2026, 20:37 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in Veeam Backup & Replication, highest risk first.
CVESeverityExploitationPublishedSummary
CVE-2024-40711Critical (9.8)Actively exploited · ransomwareA deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
CVE-2023-27532High (7.5)Actively exploited · ransomwareVulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backu…
CVE-2022-26500High (8.8)Actively exploited · ransomwareImproper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers…
CVE-2022-26501Critical (9.8)Actively exploited · ransomwareVeeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
CVE-2025-23120High (8.8)Elevated likelihood (22%)A vulnerability allowing remote code execution (RCE) for domain users.
CVE-2024-29849Critical (9.8)Elevated likelihood (17%)Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
CVE-2024-42455High (8.1)Elevated likelihood (15%)A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary fi…
CVE-2025-23121High (8.8)Elevated likelihood (12%)A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVE-2025-24286High (7.2)Elevated likelihood (11%)A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.
CVE-2022-26504High (8.8)No exploitation reportedImproper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute…
CVE-2025-59470Critical (9.0)No exploitation reportedThis vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVE-2026-21671Critical (9.1)No exploitation reportedA vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Rep…
CVE-2021-35971Critical (9.8)No exploitation reportedVeeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remoting.
CVE-2026-21669Critical (9.9)No exploitation reportedA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2025-59468Critical (9.0)No exploitation reportedThis vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
CVE-2026-21666Critical (9.9)No exploitation reportedA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2026-21667Critical (9.9)No exploitation reportedA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVE-2024-40710High (8.8)No exploitation reportedA series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcreden…
CVE-2026-21708Critical (9.9)No exploitation reportedA vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.
CVE-2020-15518High (8.8)No exploitation reportedVeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over…
CVE-2025-48984High (8.8)No exploitation reportedA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2024-29851High (7.2)No exploitation reportedVeeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
CVE-2024-39718High (8.1)No exploitation reportedAn improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
CVE-2024-29850High (8.8)No exploitation reportedVeeam Backup Enterprise Manager allows account takeover via NTLM relay.
CVE-2025-55125High (7.8)No exploitation reportedThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
CVE-2025-48983Critical (9.9)No exploitation reportedA vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
CVE-2024-40717High (8.8)No exploitation reportedA vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be co…
CVE-2024-40715High (7.7)No exploitation reportedA vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man…
CVE-2025-59469Critical (9.0)No exploitation reportedThis vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2024-29852Low (2.7)No exploitation reportedVeeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
CVE-2026-21668High (8.8)No exploitation reportedA vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
CVE-2015-5742Low (2.1)No exploitation reportedVeeamVixProxy in Veeam Backup & Replication (B&R) before 8.0 update 3 stores local administrator credentials in log files with world-readable permissions, which allows local users …
CVE-2024-42452High (8.8)No exploitation reportedA vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to sy…
CVE-2024-42457Medium (6.5)No exploitation reportedA vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management int…
CVE-2026-21670High (7.7)No exploitation reportedA vulnerability allowing a low-privileged user to extract saved SSH credentials.
CVE-2024-42456High (8.8)No exploitation reportedA vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as m…
CVE-2024-45204Medium (4.3)No exploitation reportedA vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves u…
CVE-2024-40714High (8.3)No exploitation reportedAn improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
CVE-2024-42453High (8.1)No exploitation reportedA vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to …
CVE-2024-40713High (7.8)No exploitation reportedA vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
CVE-2024-40712High (7.8)No exploitation reportedA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
CVE-2024-42451Medium (6.5)No exploitation reportedA vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an extern…

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

4 of these are being actively exploited right now.

Our Newcastle team can audit your Veeam estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.